[C:\WINDOWS\SYSTEM\NETBIOS.DLL] [N/A, N/A]
[C:\WINDOWS\SYSTEM\TCPIPDOG0.DLL] [N/A, N/A]
[PID: 4294744905][C:\WINDOWS\SYSTEM\RPCSS.EXE] [Microsoft Corporation, 4.71.2900]
[C:\PROGRAM FILES\YAHOO!\ASSISTANT\YHELPER.DLL] [Yahoo! China, 3, 0, 5, 1023]
[E:\瑞星\RISING\RFW\PNGDLL.DLL] [Beijing Rising Technology Co., Ltd., 18, 0, 0, 5]
[E:\瑞星\RISING\RFW\RSXML.DLL] [Beijing Rising Technology Co., Ltd., 19, 0, 0, 2]
[E:\瑞星\RISING\RFW\RFWCTRL.DLL] [Beijing Rising Technology Co., Ltd., 5, 0, 0, 11]
[E:\瑞星\RISING\RFW\RSCOMMON.DLL] [Beijing Rising Technology Co., Ltd., 19, 0, 0, 5]
[PID: 4294642053][E:\瑞星\RISING\RFW\RFWMAIN.EXE] [Beijing Rising Technology Co., Ltd., 5, 0, 0, 56]
[E:\瑞星\RISING\RFW\RSGUILIB.DLL] [Beijing Rising Technology Co., Ltd., 19, 0, 0, 28]
[PID: 4294674725][C:\WINDOWS\TASKMON.EXE] [Microsoft Corporation, 4.10.1998]
[PID: 4294584345][C:\WINDOWS\SYSTEM\INTERNAT.EXE] [Microsoft Corporation, 4.10.2222]
[PID: 4294579489][C:\WINDOWS\SYSTEM\SYSTRAY.EXE] [Microsoft Corporation, 4.10.2222]
[C:\PROGRAM FILES\YAHOO!\ASSISTANT\YHELPER.DLL] [Yahoo! China, 3, 0, 5, 1023]
[E:\瑞星\RISING\RAV\RSCOMMX.DLL] [rising, 18, 0, 0, 1]
[E:\瑞星\RISING\RAV\CFGDLL.DLL] [Beijing Rising Technology Co., Ltd., 18, 0, 0, 13]
[E:\瑞星\RISING\RAV\RSAPPMGR.DLL] [Beijing Rising Technology Co., Ltd., 18, 0, 0, 2]
[E:\瑞星\RISING\RAV\RSCOMMON.DLL] [Beijing Rising Technology Co., Ltd., 19, 0, 0, 5]
[PID: 4294600205][E:\瑞星\RISING\RAV\RAVTASK.EXE] [Beijing Rising Technology Co., Ltd., 19, 0, 0, 7]
[C:\WINDOWS\SYSTEM\TCPIPDOG0.DLL] [N/A, N/A]
[C:\PROGRAM FILES\YAHOO!\ASSISTANT\YNOTIFIER.DLL] [yahoo! china, 3, 0, 2, 1002]
[C:\WINDOWS\SYSTEM\NETBIOS.DLL] [N/A, N/A]
[C:\PROGRAM FILES\YAHOO!\ASSISTANT\YALLIVEEX.DLL] [Yahoo! China, 3, 0, 2, 1011]
[C:\PROGRAM FILES\YAHOO!\ASSISTANT\YALIVE.DLL] [yahoo! china, 3, 5, 7, 1109]
[C:\PROGRAM FILES\YAHOO!\ASSISTANT\YHELPER.DLL] [Yahoo! China, 3, 0, 5, 1023]
[PID: 4294619861][C:\PROGRAM FILES\YAHOO!\ASSISTANT\YLIVE.EXE] [Yahoo! China, 3, 1, 9, 1025]
[C:\PROGRAM FILES\YAHOO!\ASSISTANT\SHELL\YMENUINFO.DLL] [Yahoo! China, 3, 0, 1, 1001]
[C:\PROGRAM FILES\YAHOO!\ASSISTANT\SHELL\YIEANGEL.DLL] [Yahoo! China, 3, 0, 3, 1004]
[C:\PROGRAM FILES\YAHOO!\ASSISTANT\SHELL\YASMENU.DLL] [Yahoo! China, 3, 0, 2, 1003]
[C:\PROGRAM FILES\YAHOO!\ASSISTANT\SHELL\YASSECBLK.DLL] [Yahoo! China, 3, 1, 6, 1022]
[PID: 4294615621][C:\PROGRAM FILES\YAHOO!\ASSISTANT\YASSISTSE.EXE] [Yahoo! China, 3, 0, 5, 1008]
[PID: 4294530097][C:\WINDOWS\SYSTEM\WMIEXE.EXE] [Microsoft Corporation, 5.00.1755.1]
[C:\WINDOWS\SYSTEM\TCPIPDOG0.DLL] [N/A, N/A]
[C:\PROGRAM FILES\YAHOO!\ASSISTANT\YHELPER.DLL] [Yahoo! China, 3, 0, 5, 1023]
[PID: 4294572245][F:\上网程序\ISHARE_USER.EXE] [N/A, N/A]
[C:\WINDOWS\SYSTEM\DHCPCSVC.DLL] [N/A, N/A]
[C:\WINDOWS\SYSTEM\NETBIOS.DLL] [N/A, N/A]
[E:\瑞星\RISING\RAV\SCANNET.DLL] [Beijing Rising Technology Co., Ltd., 18, 0, 0, 5]
[E:\瑞星\RISING\RAV\USCRIPT.DLL] [Beijing Rising Technology Co., Ltd., 19, 0, 0, 17]
[E:\瑞星\RISING\RAV\EXTMAIL.DLL] [Beijing Rising Technology Co., Ltd., 19, 0, 0, 13]
[E:\瑞星\RISING\RAV\EXTOLE.DLL] [Beijing Rising Technology Co., Ltd., 19, 0, 0, 11]
[E:\瑞星\RISING\RAV\SCANELF.DLL] [Beijing Rising Technology Co., Ltd., 19, 0, 0, 11]
[E:\瑞星\RISING\RAV\UROUTINE.DLL] [Beijing Rising Technology Co., Ltd., 19, 0, 0, 19]
[E:\瑞星\RISING\RAV\RSVM.DLL] [N/A, 19, 0, 0, 13]
[E:\瑞星\RISING\RAV\SCANPACK.DLL] [Beijing Rising Technology Co., Ltd., 19, 0, 0, 18]
[E:\瑞星\RISING\RAV\NVFILE.DLL] [Beijing Rising Technology Co., Ltd., 19, 0, 0, 11]
[E:\瑞星\RISING\RAV\SCANSCT.DLL] [Beijing Rising Technology Co., Ltd., 19, 0, 0, 16]
[E:\瑞星\RISING\RAV\SCANMAC.DLL] [Beijing Rising Technology Co., Ltd., 19, 0, 0, 13]
[E:\瑞星\RISING\RAV\POSTTRT.DLL] [Beijing Rising Technology Co., Ltd., 19, 0, 0, 8]
[E:\瑞星\RISING\RAV\EXTFILE.DLL] [Beijing Rising Technology Co., Ltd., 19, 0, 0, 23]
[E:\瑞星\RISING\RAV\SCANEX.DLL] [Beijing Rising Technology Co., Ltd., 19, 0, 0, 32]
[E:\瑞星\RISING\RAV\UNEXE.DLL] [Beijing Rising Technology Co., Ltd., 19, 0, 0, 9]
[E:\瑞星\RISING\RAV\UNPACKER.DLL] [Beijing Rising Technology Co., Ltd., 19, 0, 0, 17]
[E:\瑞星\RISING\RAV\SCANEXEC.DLL] [Beijing Rising Technology Co., Ltd., 19, 0, 0, 15]
[E:\瑞星\RISING\RAV\ENGINE.DLL] [Beijing Rising Technology Co., Ltd., 19, 0, 0, 20]
[E:\瑞星\RISING\RAV\MVENGINE.DLL] [Beijing Rising Technology Co., Ltd., 19, 0, 0, 15]
[E:\瑞星\RISING\RAV\VIRUSLIB.DLL] [Beijing Rising Technology Co., Ltd., 19, 0, 0, 10]
[E:\瑞星\RISING\RAV\LIBLOAD.DLL] [Beijing Rising Technology Co., Ltd., 19, 0, 0, 16]
[E:\瑞星\RISING\RAV\PNGDLL.DLL] [Beijing Rising Technology Co., Ltd., 18, 0, 0, 5]
[E:\瑞星\RISING\RAV\RAVSCRCH.DLL] [Beijing Rising Technology Co., Ltd., 18, 0, 0, 4]
[C:\WINDOWS\SYSTEM\TCPIPDOG0.DLL] [N/A, N/A]
[C:\WINDOWS\SYSTEM\NETBIOS.DLL] [N/A, N/A]
[E:\瑞星\RISING\RAV\SCANNER.DLL] [Beijing Rising Technology Co., Ltd., 19, 0, 0, 8]
[E:\瑞星\RISING\RAV\BWLIST.DLL] [Beijing Rising Technology Co., Ltd., 19, 0, 0, 6]
[E:\瑞星\RISING\RAV\RSCOMMON.DLL] [Beijing Rising Technology Co., Ltd., 19, 0, 0, 5]
[C:\PROGRAM FILES\YAHOO!\ASSISTANT\YHELPER.DLL] [Yahoo! China, 3, 0, 5, 1023]
[E:\瑞星\RISING\RAV\RSXML.DLL] [Beijing Rising Technology Co., Ltd., 19, 0, 0, 2]
[E:\瑞星\RISING\RAV\RAVUI.DLL] [Beijing Rising Technology Co., Ltd., 19, 0, 0, 30]
[E:\瑞星\RISING\RAV\RSGUILIB.DLL] [Beijing Rising Technology Co., Ltd., 19, 0, 0, 28]
[E:\瑞星\RISING\RAV\RSCOMMX.DLL] [rising, 18, 0, 0, 1]
[E:\瑞星\RISING\RAV\CFGDLL.DLL] [Beijing Rising Technology Co., Ltd., 18, 0, 0, 13]
[E:\瑞星\RISING\RAV\RSAPPMGR.DLL] [Beijing Rising Technology Co., Ltd., 18, 0, 0, 2]
[E:\瑞星\RISING\RAV\PLUGIN\RSPGSCAN.DLL] [Beijing Rising Technology Co., Ltd., 18, 0, 0, 17]
[PID: 4294485145][E:\瑞星\RISING\RAV\RAV.EXE] [Beijing Rising Technology Co., Ltd., 19, 0, 0, 28]
[C:\WINDOWS\SYSTEM\RAVEXT.DLL] [Beijing Rising Technology Co., Ltd., 19, 0, 0, 7]
[C:\PROGRAM FILES\COMMON FILES\MICROSOFT SHARED\WEB FOLDERS\MSONSEXT.DLL] [N/A, N/A]
[E:\瑞星\RISING\RAV\RAVSCRCH.DLL] [Beijing Rising Technology Co., Ltd., 18, 0, 0, 4]
[C:\WINDOWS\SYSTEM\TCPIPDOG0.DLL] [N/A, N/A]
[C:\WINDOWS\SYSTEM\NETBIOS.DLL] [N/A, N/A]
[C:\PROGRAM FILES\YAHOO!\ASSISTANT\YHELPER.DLL] [Yahoo! China, 3, 0, 5, 1023]
[PID: 4294524289][E:\浏览器\MAXTHON\MAXTHON.EXE] [Maxthon International Ltd., 1, 5, 6, 42]
[E:\浏览器\MAXTHON\MAXZLIB.DLL] [ , 1, 0, 0, 2]
[C:\WINDOWS\SYSTEM\DHCPCSVC.DLL] [N/A, N/A]
[C:\PROGRAM FILES\YAHOO!\ASSISTANT\ASSIST\YWIPER.DLL] [Yahoo! China, 3, 0, 2, 1002]
[E:\QQ\QDSHM.DLL] [,, 1, 0, 101, 20]
[E:\瑞星\RISING\RAV\RSCOMMON.DLL] [Beijing Rising Technology Co., Ltd., 19, 0, 0, 5]
[E:\解压缩器\RAREXT.DLL] [N/A, N/A]
[C:\PROGRAM FILES\COMMON FILES\MICROSOFT SHARED\WEB FOLDERS\MSONSEXT.DLL] [N/A, N/A]
[C:\PROGRAM FILES\ACCESSORIES\HYPERTERMINAL\HTICONS.DLL] [Hilgraeve, Inc., 3.0]
[C:\PROGRAM FILES\YAHOO!\ASSISTANT\ASSIST\YASBAR.DLL] [yahoo! china, 3, 3, 0, 1091]
[E:\瑞星\RISING\RAV\RAVSCRCH.DLL] [Beijing Rising Technology Co., Ltd., 18, 0, 0, 4]
[C:\PROGRAM FILES\YAHOO!\ASSISTANT\ASSIST\YASSIST.DLL] [Yahoo! China, 3, 1, 4, 1019]
[C:\PROGRAM FILES\YAHOO!\ASSISTANT\YALLIVEEX.DLL] [Yahoo! China, 3, 0, 2, 1011]
[C:\PROGRAM FILES\YAHOO!\ASSISTANT\YALIVE.DLL] [yahoo! china, 3, 5, 7, 1109]
[C:\WINDOWS\SYSTEM\DHCPCSVC.DLL] [N/A, N/A]
[C:\WINDOWS\SYSTEM\RAVEXT.DLL] [Beijing Rising Technology Co., Ltd., 19, 0, 0, 7]
[C:\WINDOWS\SYSTEM\NETBIOS.DLL] [N/A, N/A]
[C:\PROGRAM FILES\YAHOO!\ASSISTANT\YHELPER.DLL] [Yahoo! China, 3, 0, 5, 1023]
[PID: 4294623489][C:\WINDOWS\EXPLORER.EXE] [Microsoft Corporation, 4.72.3110.1]
[C:\WINDOWS\SYSTEM\NVDD32.DLL] [NVidia Corporation, 4.12.01.0368]
[C:\WINDOWS\SYSTEM\NVARCH32.DLL] [NVidia Corporation, 4.12.01.0368]
[C:\PROGRAM FILES\YAHOO!\ASSISTANT\YHELPER.DLL] [Yahoo! China, 3, 0, 5, 1023]
[PID: 4294305165][C:\WINDOWS\SYSTEM\DDHELP.EXE] [Microsoft Corporation, 4.08.01.0881]
[PID: 4294188601][C:\WINDOWS\SYSTEM\CONIME.EXE] [N/A, N/A]
[C:\WINDOWS\SYSTEM\NETBIOS.DLL] [N/A, N/A]
[C:\WINDOWS\SYSTEM\TCPIPDOG0.DLL] [N/A, N/A]
[C:\PROGRAM FILES\YAHOO!\ASSISTANT\YHELPER.DLL] [Yahoo! China, 3, 0, 5, 1023]
[PID: 4294186313][E:\SYSTEM REPAIR ENGINEER\SRENG.EXE] [Smallfrogs Studio, 2.3.13.690]
==================================
文件关联
.TXT OK. [c:\windows\NOTEPAD.EXE %1]
.EXE OK. ["%1" %*]
.COM OK. ["%1" %*]
.PIF OK. ["%1" %*]
.REG OK. [regedit.exe "%1"]
.BAT OK. ["%1" %*]
.SCR OK. ["%1" /S]
.CHM OK. ["c:\windows\hh.exe" %1]
.HLP OK. [c:\windows\winhlp32.exe %1]
.INI OK. [c:\windows\NOTEPAD.EXE %1]
.INF OK. [c:\windows\NOTEPAD.EXE %1]
.VBS OK. [c:\windows\WScript.exe "%1" %*]
.JS OK. [c:\windows\WScript.exe "%1" %*]
.LNK OK. [{00021401-0000-0000-C000-000000000046}]
==================================
Winsock 提供者
MS.w95.spi.osp
c:\windows\SYSTEM\mswsosp.dll(Microsoft Corporation, Microsoft Windows Sockets 2.0 Service Provider)
MS.w95.spi.tcp
C:\WINDOWS\SYSTEM\TcpIpDog0.dll(N/A, N/A)
MS.w95.spi.udp
C:\WINDOWS\SYSTEM\TcpIpDog0.dll(N/A, N/A)
MS.w95.spi.raw
C:\WINDOWS\SYSTEM\TcpIpDog0.dll(N/A, N/A)
MS.w95.spi.rsvptcp
C:\WINDOWS\SYSTEM\TcpIpDogR0.dll(N/A, N/A)
MS.w95.spi.rsvpudp
C:\WINDOWS\SYSTEM\TcpIpDogR0.dll(N/A, N/A)
==================================
Autorun.inf
[C:\]
[AutoRun]
OPEN=ghost.exe
shellexecute=ghost.exe
shell\打开(&O)\command=ghost.exe
[D:\]
[AutoRun]
OPEN=ghost.exe
shellexecute=ghost.exe
shell\打开(&O)\command=ghost.exe
[E:\]
[AutoRun]
OPEN=ghost.exe
shellexecute=ghost.exe
shell\打开(&O)\command=ghost.exe
[F:\]
[AutoRun]
OPEN=ghost.exe
shellexecute=ghost.exe
shell\打开(&O)\command=ghost.exe
==================================
HOSTS 文件
N/A
==================================
API HOOK
N/A
==================================
[/CODE]